Implementing Second Factor for Single Sign-On
A systems administrator wants to add a second factor to the single sign-on portal that the organization uses. Currently, only a username and password are required. Which of the following should the administrator implement to best meet this requirement?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the ability to distinguish between factors of authentication (knowledge vs. possession), with the common trap being the selection of other knowledge-based methods like PINs or verification questions.
This question explores methods to enhance single sign-on security by adding a second factor. The correct approach involves implementing software-based TOTP, which provides a strong 'something you have' authentication layer.
Option D (Secondary PIN code) is frequently selected because it feels like a simple additional step; however, it remains a 'something you know' factor, failing to meet the requirement for a distinct second factor type.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The implementation of a second factor requires Multi-Factor Authentication (MFA), which mandates combining at least two different categories: something you know, something you have, or something you are. Software-based TOTP (Time-based One-Time Password) utilizes an authenticator app on a mobile device to generate dynamic codes. This qualifies as "something you have," effectively creating a second factor when combined with the existing username and password.Why the Other Options Are Wrong
Options A (Personal verification questions), C (Log-in image checks), and D (Secondary PIN code) all rely on static information that the user memorizes. These fall under the "something you know" category. Since the system already uses a password (also "something you know"), adding another knowledge-based factor does not increase security against credential theft or phishing in the same way possession-based factors do.Community Comment Notes
Community consensus strongly supports Option B, with users noting that TOTP represents the "something you have" factor. As noted by user psowrong, "A. Personal verification questions - something you know B. Software-based TOTP - something you have." Another commenter, LuckyAro, attempted to justify a PIN but was outvoted, highlighting the standard definition of MFA factors.Exam Strategy
When asked about adding a second factor, always look for options that introduce a new authentication domain (possession or biometrics). If the current method is knowledge-based (password), avoid selecting other knowledge-based additions like PINs or security questions.
Frequently Asked Questions
Why is a secondary PIN code not considered a second factor?
A secondary PIN is still 'something you know.' MFA requires two distinct categories, so adding another knowledge factor does not meet the strict definition.
What is the difference between TOTP and SMS OTP?
TOTP is generated locally on an app (Google Authenticator), while SMS relies on network transmission. Both are 'something you have,' but TOTP is generally more secure against SIM swapping.